2.9

CVSS3.1

CVE-2025-46393 - ImageMagick: Incorrect Calculation of Buffer Size in ImageMagick's Multispectral MIFF Processing

In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order).

πŸ“… Published: April 23, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 3:28 p.m.

7.5

CVSS3.1

CVE-2025-27580 -

NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 generates predictable tokens (that depend on username, time, and the fixed 7Dl9#dj- string) and thus allows unauthenticated users with a Common Access Card (CAC) to escalate privileges and compromise any account, inc…

πŸ“… Published: April 23, 2025, midnight πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

4.3

CVSS3.1

CVE-2025-27581 -

NIH BRICS (aka Biomedical Research Informatics Computing System) through 14.0.0-67 allows users who lack the InET role to access the InET module via direct requests to known endpoints.

πŸ“… Published: April 23, 2025, midnight πŸ”„ Last Modified: April 29, 2025, 1:52 p.m.

3.2

CVSS3.1

CVE-2025-46394 -

In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.

πŸ“… Published: April 23, 2025, midnight πŸ”„ Last Modified: Sept. 24, 2025, 2:38 p.m.

6.5

CVSS3.1

CVE-2025-47712 - Nbd: nbdkit: integer overflow triggers an assertion resulting in denial of service

A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes an internal error in the nbdkit, leading to a denial of service.

πŸ“… Published: April 23, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 4:15 a.m.

2.9

CVSS3.1

CVE-2025-43965 - ImageMagick: Incorrect Handling of Image Depth in MIFF Processing in ImageMagick

In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used.

πŸ“… Published: April 23, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 3:41 p.m.

6.5

CVSS3.1

CVE-2025-47711 - Nbdkit: nbdkit-server: off-by-one error when processing block status may lead to a denial of service

There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit server can encounter a critical internal error, lead…

πŸ“… Published: April 23, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 4:15 a.m.

9.8

CVSS3.1

CVE-2025-45427 -

In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability, which can lead to remote arbitrary code execution.

πŸ“… Published: April 23, 2025, midnight πŸ”„ Last Modified: April 30, 2025, 1:51 p.m.

7.3

CVSS3.1

CVE-2025-28028 -

TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi through the v5 parameter.

πŸ“… Published: April 23, 2025, midnight πŸ”„ Last Modified: May 6, 2025, 8:08 p.m.

7.3

CVSS3.1

CVE-2025-28022 -

TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.

πŸ“… Published: April 23, 2025, midnight πŸ”„ Last Modified: May 6, 2025, 8:35 p.m.
Total resulsts: 343968
Page 5171 of 34,397
Β« previous page Β» next page
Filters